CVE-2020-13665: Critical severity drupal vulnerability
Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the readonly set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.
Other sources
Drupal core - Less critical - Access bypass - SA-CORE-2020-006
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Drupal Core vulnerability?
The vulnerability ID for this Drupal Core vulnerability is CVE-2020-13665.
What is the severity of CVE-2020-13665?
The severity of CVE-2020-13665 is critical with a CVSS score of 9.8.
Which versions of Drupal Core are affected by CVE-2020-13665?
Drupal Core 8.8.x versions prior to 8.8.8, 8.9.x versions prior to 8.9.1, and 9.0.x versions prior to 9.0.1 are affected by CVE-2020-13665.
How does the access bypass vulnerability in Drupal Core work?
The access bypass vulnerability in Drupal Core allows JSON:API to bypass access control permissions when JSON:API is in read/write mode.
How can I fix CVE-2020-13665?
To fix CVE-2020-13665, update your Drupal Core installation to version 8.8.8, 8.9.1, or 9.0.1 or apply the necessary patches provided by Drupal.